23663 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.
CWE-79 represents a critical input validation weakness where software fails to properly sanitize user-supplied data before rendering it in web pages. Attackers typically exploit this vulnerability by injecting malicious scripts, often JavaScript, into trusted websites. When other users view the compromised page, the embedded code executes in their browsers, allowing the attacker to steal session cookies, hijack accounts, or redirect victims to phishing sites. This breach of trust undermines user privacy and application integrity. To prevent such attacks, developers must implement robust input validation and output encoding strategies. By strictly filtering incoming data and ensuring that all dynamic content is properly escaped before being processed by the browser, developers can neutralize dangerous inputs and effectively mitigate the risk of cross-site scripting vulnerabilities.
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-24470 | Yada Wiki < 3.4.1 - Contributor+ Stored XSS — Yada Wiki | 5.4 | - | 2021-08-02 |
| CVE-2021-24468 | Leaflet Map < 3.0.0 - Contributor+ Stored XSS — Leaflet Map | 5.4 | - | 2021-08-02 |
| CVE-2021-24464 | YouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSS — YouTube Embed, Playlist and Popup by WpDevArt | 5.4 | - | 2021-08-02 |
| CVE-2021-24455 | Tutor LMS < 1.9.2 - Authenticated Stored Cross-Site Scripting (XSS) — Tutor LMS – eLearning and online course solution | 5.4 | - | 2021-08-02 |
| CVE-2021-24450 | ProfilePress < 3.1.8 - Authenticated Stored XSS — User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) | 4.8 | - | 2021-08-02 |
| CVE-2021-24448 | Profile Builder < 3.4.8 - Authenticated Stored XSS — User Registration & User Profile – Profile Builder | 4.8 | - | 2021-08-02 |
| CVE-2021-24443 | Youzify < 1.0.7 - Stored Cross-Site Scripting via Biography — Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress | 5.4 | - | 2021-08-02 |
| CVE-2021-24428 | RSS for Yandex Turbo <= 1.30 - Authenticated Stored XSS — RSS for Yandex Turbo | 4.8 | - | 2021-08-02 |
| CVE-2021-24425 | myStickymenu < 2.5.2 - Authenticated Stored XSS — Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu | 4.8 | - | 2021-08-02 |
| CVE-2021-24444 | TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS) — TaxoPress – Create and Manage Taxonomies, Tags, Categories | 4.8 | - | 2021-08-02 |
| CVE-2021-35030 | Zyxel GS1900-8 跨站脚本漏洞 — GS1900-8 Firmware | 3.5 | Low | 2021-07-26 |
| CVE-2021-36092 | XSS attack using special link in email — ((OTRS)) Community Edition | 6.5 | Medium | 2021-07-26 |
| CVE-2021-21442 | XSS vulnerability in Time Accounting — Time Accounting | 4.5 | Medium | 2021-07-26 |
| CVE-2021-32792 | XSS vulnerability when using OIDCPreservePost On in mod_auth_openidc — mod_auth_openidc | 3.1 | Low | 2021-07-26 |
| CVE-2020-7390 | Sage X3 Syracuse Persistent XSS in Edit User page — X3 | 4.6 | Medium | 2021-07-22 |
| CVE-2021-1599 | Cisco Unified Customer Voice Portal Cross-Site Scripting Vulnerability — Cisco Unified Customer Voice Portal (CVP) | 5.4 | Medium | 2021-07-22 |
| CVE-2021-32745 | Reflected Cross-Site-Scripting vulnerability — online | 7.3 | High | 2021-07-21 |
| CVE-2021-22723 | EVlink City、EVlink Parking 跨站脚本漏洞 — EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) | 5.4 | - | 2021-07-21 |
| CVE-2021-22722 | 多款Schneider Electric产品跨站脚本漏洞 — EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) | 5.4 | - | 2021-07-21 |
| CVE-2021-22706 | EVlink City、EVlink Parking 和 EVlink Smart Wallbox 跨站脚本漏洞 — EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) | 5.4 | - | 2021-07-21 |
| CVE-2021-32669 | Cross-Site Scripting in Backend Grid View — TYPO3.CMS | 6.4 | Medium | 2021-07-20 |
| CVE-2021-32668 | Cross-Site Scripting in Query Generator & Query View — TYPO3.CMS | 6.4 | Medium | 2021-07-20 |
| CVE-2021-32667 | Cross-Site Scripting in Page Preview — TYPO3.CMS | 6.4 | Medium | 2021-07-20 |
| CVE-2021-24482 | Related Posts for WordPress <= 2.0.4 - Authenticated Stored XSS & XFS — Related Posts for WordPress | 4.8 | - | 2021-07-19 |
| CVE-2021-24452 | W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context) — W3 Total Cache | 6.1 | - | 2021-07-19 |
| CVE-2021-24436 | W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context) — W3 Total Cache | 6.1 | - | 2021-07-19 |
| CVE-2021-21803 | Advantech R-SeeNet 跨站脚本漏洞 — Advantech | 6.1 | - | 2021-07-16 |
| CVE-2021-21802 | Advantech R-SeeNet 跨站脚本漏洞 — Advantech | 6.1 | - | 2021-07-16 |
| CVE-2021-21801 | Advantech R-SeeNet 跨站脚本漏洞 — Advantech | 6.1 | - | 2021-07-16 |
| CVE-2021-21800 | Advantech R-SeeNet 跨站脚本漏洞 — Advantech | 6.1 | - | 2021-07-16 |
Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 23663 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.